Junglewise Threat Intelligence

CVE-2026-64475: Linux Kernel vfio/pci use-after-free in VGA arbiter registration

CVE-2026-64475 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's VFIO PCI driver, which is used to manage high-performance hardware access for virtual machines. Under specific error conditions during device setup, the system could fail to properly clean up graphics (VGA) resources, potentially leading to system instability or memory corruption. This issue primarily affects environments using hardware passthrough, such as servers running virtualized workloads with dedicated GPUs.

Technical details

A logic error in the vfio/pci implementation of the Linux kernel resulted in a missing unwind path for VGA arbiter registration. Specifically, if vfio_pci_core_register_device() fails after vfio_pci_vga_init() has succeeded, the VGA arbiter client is not released. This creates a stale registration where a callback could attempt to access a 'vdev' cookie that has already been freed, leading to a use-after-free scenario. While currently considered benign in some configurations because the callback only uses pci_dev state, it represents a significant safety risk if the driver data is followed to the vfio device. The fix introduces a call to vfio_pci_vga_uninit() in the error handling path.

Affected products

  • Linux Linux 5.10.37 to 5.10.261, 5.11.21 to 5.12, 5.12.4 to 5.13

Timeline

  • 2026-07-25: disclosed
  • 2026-07-25: advisory
  • 2026-07-24: patched

References